CVE-2008-6449

Cross-site request forgery (CSRF) vulnerability in multiple Century Systems routers including XR-410 before 1.6.9, XR-510 before 3.5.3, XR-440 before 1.7.8, and other XR series routers from XR-510 to XR-730 allows remote attackers to modify configuration as the administrator via unknown vectors.
Configurations

Configuration 1 (hide)

OR cpe:2.3:h:centurysys:xr-1100:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-410:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-410-l2:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-440:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-510:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-540:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-640:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-640-l2:*:*:*:*:*:*:*:*
cpe:2.3:h:centurysys:xr-730:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:56

Type Values Removed Values Added
References () http://jvn.jp/en/jp/JVN67573833/index.html - () http://jvn.jp/en/jp/JVN67573833/index.html -
References () http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000042.html - () http://jvndb.jvn.jp/ja/contents/2008/JVNDB-2008-000042.html -
References () http://secunia.com/advisories/31173 - () http://secunia.com/advisories/31173 -
References () http://www.centurysys.co.jp/support/xr_common/JVN67573833.html - Vendor Advisory () http://www.centurysys.co.jp/support/xr_common/JVN67573833.html - Vendor Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/43949 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/43949 -

Information

Published : 2009-03-09 14:30

Updated : 2024-11-21 00:56


NVD link : CVE-2008-6449

Mitre link : CVE-2008-6449

CVE.ORG link : CVE-2008-6449


JSON object : View

Products Affected

centurysys

  • xr-440
  • xr-410
  • xr-510
  • xr-540
  • xr-640-l2
  • xr-1100
  • xr-730
  • xr-410-l2
  • xr-640
CWE
CWE-352

Cross-Site Request Forgery (CSRF)